unira
  • Home
  • Services
  • Contact
  • ES EN
ES EN
Let's talk
Home Services Contact
ES EN
Let's talk
Legal documentation

Privacy and Personal Data Processing Policy

Version 1.0

Last updated: June 16, 2026

Download DOCX
Privacy Policy Terms of Service Data Deletion
Contents
  1. Purpose and scope
  2. Principles
  3. Role regarding data
  4. Nature of the data
  5. Sensitive data and identity documents
  6. Authorization by the data subject
  7. Purpose of the collected data
  8. Data processing through the use of artificial intelligence (AI)
  9. Providers, subprocessors and international data transfers
  10. Processing of financial, commercial and credit information
  11. Information security and incident management
  12. Data retention
  13. Obligations of UNIRA SAS as data controller and data processor for data processing and protection
  14. Rights of personal data subjects
  15. Habeas data and data deletion
  16. National Database Registry (RNBD)
  17. Processing of data of minors
  18. Term and miscellaneous provisions

Entity: UNIRA SAS · NIT 902.056.355

Public location: Medellín, Colombia

Contact email: contact.unira@gmail.com

Download Privacy Policy in Word

Download original Spanish DOCX

This English version is provided for convenience. In case of discrepancy, the Spanish version shall prevail.

UNIRA S.A.S., a legally incorporated company identified with NIT 902.056.355, with its main operation in the city of Medellín, Colombia, is a technology company that offers B2B software solutions, automation, modular CRM, integrations, custom development, artificial intelligence agents and conversational automation, including solutions connected with Meta WhatsApp Business Platform; by means of this document, it establishes and adopts the Privacy and personal data processing policies for its users, customers and third parties involved in the services offered by the company, subject to Law 1581 of 2012, Decree 1074 of 2015 (in particular Chapters 25 and 26 of Title 2, Part 2, Book 2) and Law 1266 of 2008.

This Privacy Policy is based mainly on the Colombian legal framework, especially on:

  • Article 15 of the Political Constitution, which recognizes the fundamental right to habeas data and personal and family privacy.
  • Law 1581 of 2012, the Statutory Personal Data Protection Law, which establishes the general personal data protection regime in Colombia.
  • Decree 1074 of 2015, the Single Regulatory Decree of the Commerce, Industry and Tourism Sector, in particular Chapter 25 (which compiled Decree 1377 of 2013) and Chapter 26, which partially regulate Law 1581 of 2012 and govern, among other matters, the minimum content of processing policies, authorization by the data subject, privacy notices and the National Database Registry (RNBD).
  • Law 1266 of 2008, which regulates the handling of information contained in personal databases of a financial, credit, commercial and services nature, as well as information from third countries.

This policy does not reduce or limit the rights, guarantees or duties established in those rules. In the event of conflict or omission, the provisions of the applicable law shall prevail.

For purposes of applying the Privacy and Personal Data Processing Policy, and in compliance with Law 1581 of 2012 and Decree 1074 of 2015, the following terms are established for understanding:

  • Personal data: any information linked to or that may be associated with one or more identified or identifiable natural persons.
  • Sensitive data: personal data that affects the privacy of the data subject or whose improper use may generate discrimination, such as health data, racial or ethnic origin, political orientation, religious or philosophical beliefs, union membership, biometric data and data relating to sexual life.
  • Data subject: natural person whose personal data is subject to processing.
  • Data controller: natural or legal person that, by itself or jointly with others, decides on the database and/or the processing of the data.
  • Data processor: natural or legal person that, by itself or jointly with others, processes personal data on behalf of the data controller.
  • Processing: any operation on personal data, such as collection, storage, use, circulation, transfer, transmission or deletion.
  • Authorization: prior, express and informed consent of the data subject to carry out the processing of their personal data.
  • Privacy notice: communication addressed to the data subject at the time of collection of their data, through which they are informed of the existence of this policy, how to access it and the main characteristics of the processing.
  • Database: organized set of personal data subject to processing.
  • Transfer: sending of personal data by Unira, as data controller or data processor, to a recipient that is in turn the data controller and is located inside or outside Colombia.
  • Transmission: processing of personal data that implies its communication inside or outside the territory of Colombia, when its purpose is processing by the processor on behalf of the controller.

Purpose and scope

This document establishes the conditions, duties and rights of UNIRA SAS when collecting, using, storing, sharing, protecting and/or deleting personal data in relation to its websites, applications, CRM, contracted modules, automations, integrations, development services, WhatsApp AI Agents and other B2B services offered by UNIRA SAS.

Our services are mainly directed at companies, businesses, ventures and operational teams. They are not designed as a mass consumer application for end users. However, in providing the service, we may process personal data of our customers' end users, such as guests, leads, contacts, prospects or final customers.

Principles

In the processing of personal data, UNIRA SAS shall apply the principles established in Article 4 of Law 1581 of 2012, namely:

  • Legality: processing is subject to the provisions of the law and the other provisions that develop it.
  • Purpose: processing obeys a legitimate purpose informed to the data subject, and the data may not be used for different purposes.
  • Freedom: processing is carried out only with the prior, express and informed consent of the data subject, except for the exceptions provided by law; the data is not obtained or disclosed without such authorization.
  • Truthfulness or quality: information subject to processing must be truthful, complete, accurate, updated, verifiable and understandable; UNIRA SAS shall not process partial, incomplete, fragmented or misleading data.
  • Transparency: the data subject is guaranteed the right to obtain from the controller or processor, at any time and without restrictions, information about the existence of data concerning them.
  • Restricted access and circulation: processing is subject to the limits derived from the nature of the data and the law; data shall not be available on the internet or other mass disclosure media, unless access is technically controllable to provide restricted knowledge to data subjects or authorized third parties.
  • Security: information subject to processing is managed with the technical, human and administrative measures necessary to provide security to the records, preventing their adulteration, loss, consultation, unauthorized or fraudulent use or access.
  • Confidentiality: persons involved in processing are obliged to guarantee the confidentiality of the information, even after their relationship with any of the tasks comprising the processing has ended.

Role regarding data

UNIRA SAS may act in different roles depending on the context:

  • As data controller with respect to the data that UNIRA SAS will collect and use for its own business operation, contractual relationship, sales, support, billing, security, account administration and improvement of its services.
  • As data processor with respect to the data that our B2B customers upload, manage, integrate or process through UNIRA SAS CRM, contracted modules, automations, WhatsApp AI Agents, n8n flows, integrations or custom developments, when UNIRA SAS processes such data following the customer's instructions.

In some scenarios, the role may be mixed. That is, UNIRA SAS may be the data controller for the contact data of the administrator of a customer account, and processor with respect to the data of end users that such customer processes within the platform or conversational agent.

Likewise, the B2B customer may be responsible for determining the main purposes of processing the data of its end users, obtaining the necessary authorizations, informing its users about the processing and complying with the laws, policies and requirements applicable to its activity.

Nature of the data

The data collected and/or processed by UNIRA SAS will depend on the contracted service, the technical configuration, the enabled integrations and the information provided by the customer or its users.

Data of B2B customers and administrative users

  • Company name or business name, NIT or other business identification data.
  • Name, position, email, phone number and contact details of administrators, legal representatives, internal users, stakeholders or customer managers.
  • Billing data, commercial information, quotations, proposals, service orders, payments, support, contractual history and communications with UNIRA SAS.
  • Users, roles, permissions, activity, account configuration, contracted modules and operational preferences within app.unira.tech or other enabled interfaces.

Data processed in UNIRA CRM and monthly-fee modules

  • Data of prospects, leads, commercial contacts and final customers of the B2B customer.
  • Tasks, calendar events, documents, files, internal notes, statuses, pipeline stages, operational records and data entered by the customer or its users.
  • Usage metadata, activity, audit, access records, technical logs, errors and data necessary for support, security, operation, continuity and billing.

Data processed in software development, automations and integrations

  • Technical and functional requirements, project documents, test data, production data provided by the customer, processed files, automation outputs and results generated by artificial intelligence.
  • Credentials, integration keys, tokens, secrets or technical accesses when necessary to operate an integration, seeking to use reasonable security practices and avoiding storing secrets in plain text when possible.
  • Execution logs, errors, traceability, technical metrics, support records and data necessary to debug, maintain, improve or secure the services.

Data processed in WhatsApp AI Agents and Meta WhatsApp Business Platform

When UNIRA SAS provides conversational agent services through WhatsApp, data related to Meta WhatsApp Business Platform, Cloud API, Embedded Signup, WhatsApp webhooks, n8n, Unira CRM and artificial intelligence providers may be stored and processed.

  • WABA ID, phone_number_id, WhatsApp number, display phone number, onboarding status, configuration status and technical events associated with the integration.
  • WhatsApp identifiers, such as wa_id, message_id, status_id, timestamps, delivery statuses, webhook events, integration errors and technical logs.
  • Incoming and outgoing messages, conversation text, fragments or complete conversations when applicable, files, images, documents, audio or other media sent by end users or by the customer.
  • Contact data of end users, such as name, WhatsApp number, email, cell phone, booking data, preferences, requirements, requests, internal notes, tags, lead status or interaction history.
  • Agent configuration, language, time zone, escalation rules, base instructions, prompts, knowledge sources, sources of knowledge, operational metrics and human escalation records.

Sensitive data and identity documents

Pursuant to Article 5 of Law 1581 of 2012, sensitive data requires reinforced processing and, in general, explicit authorization from the data subject. UNIRA SAS does not seek to collect sensitive data as an ordinary part of its services. Customers must not upload, send or request sensitive data, medical, biometric, regulated financial, critical legal information, passwords, credentials, identity documents or highly confidential information, unless strictly necessary for the contracted use case, there is an applicable legal basis or authorization, and the customer has informed and obtained the corresponding authorizations.

When a use case reasonably requires data such as name, ID number, email or cell phone, among others, for booking, validation or service provision processes, the B2B customer shall be responsible for ensuring that such data is collected and used lawfully, proportionally and securely. UNIRA SAS may reject, limit, suspend or delete data that it considers unnecessary, excessive, sensitive or risky for the service.

Authorization by the data subject

Except for the exceptions provided in Article 10 of Law 1581 of 2012 (among others, information required by a public entity in the exercise of its legal functions, data of a public nature, cases of medical or health urgency, processing authorized by law for historical, statistical or scientific purposes, or data related to the Civil Registry of Persons), the processing of personal data by UNIRA SAS requires the prior, express and informed authorization of the data subject, for which such authorization may be obtained in writing, orally or through unequivocal conduct by the data subject that reasonably allows the conclusion that it was granted, such as accepting terms and conditions in a web form or application, checking an acceptance box, continuing a conversation with a WhatsApp agent after receiving the corresponding privacy notice, or voluntarily providing their data in a form, survey or contact request.

When the data is collected directly by a B2B customer, it is the responsibility of that customer, as data controller with respect to its own end users, to obtain the corresponding authorization, inform the purposes of processing and keep proof of such authorization, without prejudice to UNIRA SAS reasonably cooperating to facilitate compliance with this obligation.

The data subject may revoke the authorization and/or request the deletion of their personal data at any time, unless there is a legal or contractual duty that prevents immediate deletion, as explained later in this policy.

At data collection points (web forms, applications, WhatsApp channels or others), UNIRA SAS and/or its customers shall seek to make available to the data subject a brief privacy notice indicating the existence of this policy, the purpose of processing and how to access its full text.

Purpose of the collected data

UNIRA SAS may use the data described in this policy for the following purposes:

  • To provide, configure, operate, maintain and improve the services contracted by B2B customers.
  • To create, administer and support accounts, users, roles, permissions, modules, automations, integrations and artificial intelligence agents.
  • To process communications, messages, requests, bookings, leads, tasks, documents, events and operational flows of the customer.
  • To operate WhatsApp AI Agents, receive and send messages, process webhook events, execute automations, activate human escalation and record events necessary for traceability.
  • To process data with providers of infrastructure, communication, artificial intelligence, orchestration, email, storage, monitoring, security or support.
  • To invoice, collect, manage payments, administer accounts receivable, issue electronic invoicing, comply with accounting, tax and legal obligations.
  • To provide support, diagnose errors, debug failures, prevent abuse, monitor availability, maintain security, perform technical audits and respond to incidents.
  • To comply with legal, contractual, regulatory obligations or requirements from competent authorities.
  • To protect the rights, security, reputation and integrity of UNIRA SAS, its customers, users and third parties.

Data processing through the use of artificial intelligence (AI)

UNIRA SAS services may use artificial intelligence models, proprietary, local or provided by third parties, for tasks such as conversational support, classification, extraction, summarization, response generation, message analysis, flow automation, agent support and operational enrichment, for which UNIRA SAS may change, combine or replace artificial intelligence, infrastructure or automation providers without prior notice, according to criteria of cost, availability, performance, security, quality, technical compatibility or operational need. When a change materially affects the privacy, security or nature of the service, UNIRA SAS shall seek to communicate it through reasonable means.

UNIRA SAS shall not use customer data to train its own or third-party general models, unless expressly authorized by the customer or unless the data has been duly anonymized or aggregated so that it does not identify the customer or its end users. External artificial intelligence providers may process data according to their own applicable conditions, configurations and agreements.

Artificial intelligence systems may produce incorrect, incomplete, outdated or context-inappropriate responses. The customer must review the configuration, knowledge sources, instructions, flows and relevant results of the agent, especially before putting it into production or using it in sensitive interactions.

Providers, subprocessors and international data transfers

Pursuant to Article 26 of Law 1581 of 2012, in accordance with Chapter 25 of Decree 1074 of 2015, it is prohibited to transfer personal data to countries that do not provide adequate levels of data protection, unless one of the exceptions provided by law applies, including: express and unequivocal authorization by the data subject for the transfer; transfer necessary for the performance of a contract between the data subject and the controller, or for the execution of pre-contractual measures provided that authorization from the data subject is obtained; transfer legally required to safeguard the public interest or for the administration of justice; transfer of data that is public in nature; or transfer for which contractual clauses, binding corporate rules or other instruments recognized by the Superintendence of Industry and Commerce exist that guarantee adequate levels of protection.

To provide its services, UNIRA SAS may use national or international providers and subprocessors, including, without limitation, cloud, hosting, infrastructure, database, storage, security, email, messaging, Meta WhatsApp Business Platform, artificial intelligence, orchestration, automation, monitoring, support and internal tool providers.

Some of these providers may be located or process data outside Colombia. In such event, UNIRA SAS shall seek for the transfer to be covered by one of the scenarios indicated above, including authorization from the data subject or the customer, contractual clauses or equivalent guarantees, and shall apply reasonable contractual, technical and organizational measures to protect the information according to the nature of the service, the type of data and the applicable law.

The customer acknowledges that services such as WhatsApp, Meta, artificial intelligence providers, cloud services and third-party APIs may have their own terms, policies, security measures, availability and data processing practices.

Processing of financial, commercial and credit information

In the development of its commercial activity, UNIRA SAS may process data of a financial, credit and commercial nature, mainly related to billing, payment history and contractual relationships with its B2B customers, as well as, in certain cases, data that its customers process within Unira CRM, contracted modules or conversational agents regarding their own end users.

Therefore, it shall fully apply Law 1266 of 2008, which regulates the handling of financial, credit, commercial, services information and information from third countries, and distinguishes between sources of information (those who provide the data), information operators (those who administer databases, such as credit bureaus) and users of the information.

UNIRA SAS does not operate as a credit bureau or information operator within the meaning of Law 1266 of 2008. When UNIRA SAS processes information on payments, billing or contractual compliance of its own B2B customers, it shall apply the principles set forth in Article 4 of said law, in particular truthfulness and quality of records, purpose, restricted circulation, temporality of information, comprehensive interpretation of constitutional rights, security and confidentiality. Therefore, if at any time UNIRA SAS reports negative information on a customer's payment behavior to a credit bureau, it shall do so in compliance with the duty of prior notification to the data subject established in Article 12 of Law 1266 of 2008.

When a B2B customer uses Unira CRM, the contracted modules, WhatsApp agents or other UNIRA SAS tools to manage financial, credit or commercial information of its own end users, such customer shall act as source, operator and/or user of the information for purposes of Law 1266 of 2008, and shall be responsible for complying with the corresponding obligations, including prior notification to the data subject before reporting negative information. In these cases, UNIRA SAS shall act as data processor, applying reasonable confidentiality, security and access control measures, and using such information exclusively to provide the service contracted by the customer.

Information security and incident management

UNIRA SAS shall implement and seek to maintain reasonable technical, human and administrative measures to protect data against unauthorized access, loss, alteration, misuse or unauthorized disclosure. These measures may include, as applicable, HTTPS, access control, environment separation, credentials per environment, technical records, backups, integration review, permission control, secret minimization practices and server-to-server security measures.

UNIRA SAS seeks not to store tokens, secrets or credentials in plain text when possible and continuously works to improve its security controls. No technological system is completely secure; therefore, UNIRA SAS does not guarantee absolute security or uninterrupted availability.

In compliance with literal n) of Article 17 of Law 1581 of 2012, when UNIRA SAS identifies a breach of security codes or a risk in the administration of data subjects' information that may materially affect them, it shall inform the Superintendence of Industry and Commerce and, when relevant, the affected customers and data subjects, as soon as it becomes aware of the event and without unjustified delay, adopting reasonable measures to contain, investigate and mitigate the incident.

Data retention

UNIRA SAS shall retain data for the time necessary to provide the service, fulfill authorized purposes, address support, security, audit, billing, legal compliance, fraud prevention, dispute resolution or defense against claims.

  • Raw WhatsApp webhook payloads: up to 30 days by default, unless they are necessary for security, debugging, audit, service continuity or legal reasons.
  • Normalized conversations, CRM data, agent records and operational data: while the customer account or contracted service remains active, unless a shorter period is configured or requested and technically possible.
  • Technical logs, errors, execution, security and idempotency records: generally between 90 and 180 days, unless there is a different operational, contractual or legal need.
  • Backups: generally up to 14 days, subject to technical configuration and available backup cycles.
  • Billing, contract, support, audit, tax and legal records: for the time required or permitted by applicable law.

Upon termination of a contractual relationship, UNIRA SAS may retain certain data for a reasonable period for account closure, support, audit, legal compliance, billing, abuse prevention or defense against claims. Deletion of data in backups may take additional time due to technical backup cycles.

Obligations of UNIRA SAS as data controller and data processor for data processing and protection

Pursuant to Articles 17 and 18 of Law 1581 of 2012, and depending on whether it acts as data controller or data processor, UNIRA SAS undertakes, among others, to:

  • Guarantee the data subject, at all times, the full and effective exercise of the right to habeas data.
  • Request and retain, when applicable, a copy of the authorization granted by the data subject or by the B2B customer responsible for the processing.
  • Properly inform the data subject of the purpose of the collection and the rights they have by virtue of the authorization granted.
  • Keep the information under the security conditions necessary to prevent its adulteration, loss, consultation, unauthorized or fraudulent use or access.
  • Process the inquiries and claims submitted by data subjects under the terms indicated in this policy and applicable law.
  • Process only the data for which it is authorized and respect the security conditions and instructions of the controller, when acting as processor.
  • Inform the Superintendence of Industry and Commerce when breaches of security codes occur and there are risks in the administration of data subjects' information.
  • Comply with the instructions and requirements issued by the Superintendence of Industry and Commerce.

These duties are understood to be incorporated into this policy and do not replace the additional obligations that UNIRA SAS assumes by contract with its B2B customers.

Rights of personal data subjects

In accordance with Article 8 of Law 1581 of 2012 and other applicable rules, data subjects may exercise, as applicable, the rights to know, update, rectify, request proof of authorization, be informed about the use of their data, file complaints with the competent authority, revoke authorization, request deletion and access their personal data free of charge.

When UNIRA SAS acts as data processor on behalf of a B2B customer, some requests may be addressed directly by the customer as data controller. In those cases, UNIRA SAS may coordinate with the customer to address the request in accordance with applicable law and the customer's instructions.

Habeas data and data deletion

To exercise habeas data or privacy rights, or to request data deletion, the data subject may write to contact.unira@gmail.com with the subject "Personal data request" or "Data deletion request". The area responsible for handling inquiries, claims and requests related to personal data is the administrative and legal area of UNIRA SAS, which may be contacted through the email above.

The request must include, at minimum:

  • Full name of the requester.
  • Identity document or sufficient information to verify identity, when applicable.
  • Email and/or WhatsApp number associated with the request.
  • Related company or B2B customer, if applicable.
  • Clear description of the request: inquiry, update, correction, deletion, revocation, account deletion or other.
  • Supporting materials or documents that the requester wishes to provide.

UNIRA SAS may request additional information to verify identity, confirm that the requester is authorized, prevent improper access or coordinate with the B2B customer responsible for the data. For WhatsApp end users, UNIRA SAS may validate the associated number, request confirmation through the corresponding channel or coordinate with the B2B customer that enabled the service.

Inquiries shall be addressed within a maximum of ten (10) business days, extendable in the cases permitted by law; claims for correction, update or deletion shall be addressed, as a general rule, within a maximum of fifteen (15) business days, extendable in the cases permitted by law. If the claim is incomplete, the requester shall be required within five (5) days following receipt to correct the deficiencies; if one (1) month has elapsed since such request and the requester has not submitted the required information, it shall be understood that they have withdrawn the claim.

UNIRA SAS may delete, anonymize or block data when legally and technically appropriate. However, some deletion requests may be limited by legal, accounting, tax, contractual, security, audit, fraud prevention, dispute resolution, defense against claims obligations or by reasonable technical restrictions, including temporary backups.

If an end user requests deletion of data associated with a B2B customer, UNIRA SAS may address the request directly when possible, or coordinate with the B2B customer responsible for the processing to execute the request in accordance with applicable law.

National Database Registry (RNBD)

In accordance with Article 25 of Law 1581 of 2012 and Chapter 26 of Title 2, Part 2, Book 2 of Decree 1074 of 2015, as amended by Decree 090 of 2018, companies and nonprofit entities whose total assets are equal to or greater than 100,000 Tax Value Units (UVT), as well as public entities, are required to register their databases in the National Database Registry (RNBD), administered by the Superintendence of Industry and Commerce. Micro and small enterprises are not required to carry out such registration, without prejudice to their duty to comply with the general personal data protection regime.

Processing of data of minors

Pursuant to Article 7 of Law 1581 of 2012, the processing of personal data of children and adolescents is prohibited, except when it concerns data of a public nature, the processing responds to and respects the best interests of the minor, and respect for their fundamental rights is ensured.

UNIRA SAS services are directed at companies and professionals, and are not designed to intentionally collect data from minors. UNIRA SAS customers must not upload, send or enable the collection of data from minors through Unira CRM, contracted modules, automations or WhatsApp AI Agents, unless they have the express authorization of the minor's legal representative, there is a legal basis that permits it, and the best interests of the minor and the other conditions provided by law are guaranteed.

If it is identified or reported that data from minors has been collected without the required authorizations or conditions, UNIRA SAS may suspend the processing, block, delete or request that the responsible B2B customer delete such data, without prejudice to any additional measures that may correspond under the law.

Term and miscellaneous provisions

UNIRA SAS may update this Privacy Policy to reflect legal, technical, operational, commercial or service changes. The current version shall be published on the UNIRA SAS website with its last updated date. When a change is material, reasonable efforts shall be made to communicate it through reasonable means.

This policy enters into force on the date of its last update and shall remain in force while UNIRA SAS processes personal data in the development of its activity, without prejudice to periodic updates made in accordance with the provisions herein. The associated databases shall remain valid for the time during which the information is maintained and used for the purposes described in this policy.

Last updated: June 16, 2026.

unira

Intelligent automation, clear execution.

AI & Automation Agency · unira.tech

Navigation

  • Home
  • Services
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Data Deletion
© Unira · AI & Automation Agency. All rights reserved.
ES EN
Privacy Terms Data Deletion